Kora Payment Gateway Integration
Connect Kora to PayLexer to accept cards, bank transfers, mobile money and EFTs across Nigeria, Kenya, Ghana, South Africa and other African markets.
Kora is a pan-African payments infrastructure company, founded in Nigeria and known previously as Korapay. Through a single integration, Kora lets merchants collect the payment methods African shoppers actually use - cards, bank transfers, mobile money, instant EFTs and virtual bank accounts - across Nigeria, Kenya, Ghana, South Africa and several other markets.
- Supported Regions (Merchant Accounts): Africa (including Nigeria, Kenya, Ghana, South Africa, Egypt, Cameroon, Ivory Coast, Tanzania and Zambia) - view full list
- Supported Currencies: NGN, KES, GHS, ZAR, USD, EGP, XAF, XOF, TZS - view full list
Supported Features
- Hosted checkout that redirects shoppers to Kora's secure payment page
- Card payments, bank transfers, mobile money, instant EFTs and virtual bank accounts
- Full refunds
- Partial refunds
- Real-time webhook notifications for payments and refunds, secured with HMAC-SHA256 signatures
- Automatic recovery of refunds issued directly inside the Kora dashboard
- Separate test and live credentials for safe testing
Kora does not support subscriptions or recurring billing in PayLexer. Kora's scheduled billing is limited to Nigerian bank direct debit, which requires the customer's bank account details and sits outside the checkout flow, so only one-time payments are available.
Before You Start
Make sure you have:
- Kora Account – Don't have one? Sign up for Kora →
- PayLexer Account – Required to configure the integration. Create your account →
- A website where you want to integrate
Looking for a different payment processor? View all supported gateways →
Configuring Kora
You need a Secret Key and Public Key from Kora for this integration.
Getting API Credentials
Log in to Kora
Sign in to your Kora dashboard.

Choose your environment
Switch the dashboard to Test Mode to collect sandbox credentials, or leave it in live mode to collect production credentials. Kora issues a completely different set of keys for each, so collect them one environment at a time.

Open API Configuration
Go to Settings → Product & Payment Settings → API Configuration. You will see an API Keys section containing your Public Key and Secret Key.

Copy both keys
Copy the Public Key and the Secret Key using the copy icon beside each value. Keep the Secret Key private - it authorises payments and refunds on your account.
The Encryption Key shown on the same screen is not required. It is only used for direct card integrations, and PayLexer uses Kora's hosted checkout, so card details are entered on Kora's own page and never reach PayLexer.
Adding Credentials to PayLexer
Open PayLexer Dashboard
Log in to your PayLexer dashboard and navigate to Payment Gateways → Kora.

Enter your credentials
Paste the Secret Key and Public Key you copied from Kora into the corresponding fields.

Understanding Live/Production and Sandbox Settings:
| Environment | Purpose |
|---|---|
| Live / Production | Used for real transactions. |
| Test / Sandbox | Used for testing only. No real money is processed. |
How PayLexer selects credentials:
- Debug/Test mode ON → Test credentials are used
- Debug/Test mode OFF → Live credentials are used
Test and save
Click Save to save your configuration and verify your credentials. Click Verify Connection to test the connection.

Configuring Webhooks (Mandatory)
Webhooks enable real-time payment updates and significantly improve reliability.
Benefits of Webhooks:
- Instant payment status updates
- Automatic refund processing
- Dispute notifications
Copy your PayLexer webhook URL
On the Payment Gateways → Kora page in PayLexer, copy the Webhook URL. It is generated for your account and shown as a read-only field.

Open Notification URLs in Kora
In your Kora dashboard, go to Settings → Product & Payment Settings → API Configuration and scroll to the Notification URLs section.
Paste and save the URL
Paste the PayLexer webhook URL into the notification URL field and save.

Kora uses a single notification URL for your whole account rather than one per payment, and payment confirmations are delivered to it. If this is left blank, orders may stay pending even after a customer has paid.
There is no separate webhook secret to enter. Kora signs every notification with your Secret Key, so saving your credentials is all PayLexer needs to verify that a notification genuinely came from Kora.
Integrate Kora to Your Website
If you have already added and configured your site, you can enable Kora in your existing setup.
Go to Websites
Navigate to Websites in your PayLexer dashboard.
Edit your website
Click the Edit Icon of your added website.

Enable Kora
Click the checkbox to enable Kora for the website.

If you haven't added a website yet, Continue to Add Your Website →
Troubleshooting
Best Practices
- Test in sandbox before enabling production, using your Kora test keys with Debug/Test mode ON
- Save your PayLexer webhook URL in Kora's Notification URLs before taking live payments
- Enable the currencies and payment channels you plan to sell with in your Kora dashboard first
- Keep order totals above Kora's minimum amount, especially when testing
- Use real customer email addresses, as Kora rejects reserved domains such as
.local - Keep your Secret Key private and rotate it in Kora if you suspect it has been exposed
- Reconcile your PayLexer orders against your Kora dashboard periodically
FAQs
Still Have Questions?
- Kora Support: Kora Help Center
- PayLexer Support: Contact Support